Gordon Keehn wrote:Dotan Cohen wrote:The primary reason for not logging in as root unnecessarily is not due to malicious web activity, but for protection against our own typo's (rm -rf core *; for instance). But I remember when most web attacks were against unix (before windows even existed). If linux becomes the dominant OS on the web, we will become the dominant target again. Much of the current security and safety in linux is because of the uucp and mail attacks agaist unix boxes in the late 70's and early 80's. What really pisses me off about Microcsoft is that they use all sorts of el-neato web features to sell their system, then once someone buys it, they tell them they have to turn all that neat stuff off to secure their box. No matter what the operating system, it is always bad to login as root unnecessarily. I remember back in the early 70's my friends and I in high school all had super-user accounts on MIT's multics system because the administrator left a terminal logged in when he went to get coffee. |